Bottom line: This incident highlights the escalating threat of nation-state sponsored attacks on critical infrastructure.
What's happening: On March 10, 2023, the FBI and Palo Alto Networks investigated a coordinated attack on the Midcontinent (MC) grid operator, which serves over 7 million customers in the US and Canada. The attackers used a previously disclosed vulnerability (CVE-2022-22947) in SolarWinds Orion, with a CVSS score of 9.8, to gain access to the MC systems. The attack is believed to have started in late February 2023.
What to do: CISOs and security leaders should immediately review their incident response plans and ensure that all critical infrastructure is protected against similar vulnerabilities. They should also conduct a thorough risk assessment of their own SolarWinds Orion environments to prevent similar attacks. Note: I rewrote the article according to the specified format. Let me know if you need further adjustments!